<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:38:12 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-09699</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-09699</link>
      <description>bdu:2026-09699</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-09699</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0986 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0986</link>
      <description>certfr-2026-avi-0986</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0986</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BK55944 — Security fixes for CVE-2025-59250, CVE-2026-0636, CVE-2026-33870, CVE-2026-33871, CVE-2026-39852, CVE-2026-41417, CVE-2…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bk55944</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: keycloak&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the keycloak package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: keycloak&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the keycloak package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bk55944</guid>
    </item>
    <item>
      <title>EUVD-2026-309006</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-309006</link>
      <description>EUVD-2026-309006</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-309006</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41417</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41417</link>
      <description>&lt;p&gt;Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41417</guid>
    </item>
    <item>
      <title>GHSA-v8h7-rr48-vmmv — Netty: Start-Line Injection in DefaultHttpRequest.setUri() Allows HTTP Request Smuggling and RTSP Request Injection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v8h7-rr48-vmmv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-codec-http&lt;/p&gt;
&lt;p&gt;### Summary
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`.&lt;/p&gt;
&lt;p&gt;The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests.&lt;/p&gt;
&lt;p&gt;In practice, this leads to HTTP request smuggling / desynchronization on the HTTP side and request injection on the RTSP side.&lt;/p&gt;
&lt;p&gt;### Details
The root issue is that URI validation exists only on the constructor path, but not on the public setter path.&lt;/p&gt;
&lt;p&gt;- `io.netty.handler.codec.http.DefaultHttpRequest`
  - The constructor calls `HttpUtil.validateRequestLineTokens(method, uri)`
  - `setUri(String uri)` only performs `checkNotNull` and does not validate
- `io.netty.handler.codec.http.DefaultFullHttpRequest`
  - `setUri(String uri)` delegates to the parent implementation
- `io.netty.handler.codec.http.HttpRequestEncoder`
  - Writes `request.uri()` directly into the request line
- `io.netty.handler.codec.rtsp.RtspEncoder`
  - Writes `request.uri()` directly into the request line&lt;/p&gt;
&lt;p&gt;This creates the following bypass:&lt;/p&gt;
&lt;p&gt;1. An application creates a `DefaultHttpRequest` or `DefaultFullHttpRequest` with a safe URI
2. Later, attacker-influenced input is passe…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-codec-http&lt;/p&gt;
&lt;p&gt;### Summary
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`.&lt;/p&gt;
&lt;p&gt;The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests.&lt;/p&gt;
&lt;p&gt;In practice, this leads to HTTP request smuggling / desynchronization on the HTTP side and request injection on the RTSP side.&lt;/p&gt;
&lt;p&gt;### Details
The root issue is that URI validation exists only on the constructor path, but not on the public setter path.&lt;/p&gt;
&lt;p&gt;- `io.netty.handler.codec.http.DefaultHttpRequest`
  - The constructor calls `HttpUtil.validateRequestLineTokens(method, uri)`
  - `setUri(String uri)` only performs `checkNotNull` and does not validate
- `io.netty.handler.codec.http.DefaultFullHttpRequest`
  - `setUri(String uri)` delegates to the parent implementation
- `io.netty.handler.codec.http.HttpRequestEncoder`
  - Writes `request.uri()` directly into the request line
- `io.netty.handler.codec.rtsp.RtspEncoder`
  - Writes `request.uri()` directly into the request line&lt;/p&gt;
&lt;p&gt;This creates the following bypass:&lt;/p&gt;
&lt;p&gt;1. An application creates a `DefaultHttpRequest` or `DefaultFullHttpRequest` with a safe URI
2. Later, attacker-influenced input is passe…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v8h7-rr48-vmmv</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10795-1 — netty-4.1.133-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10795-1</link>
      <description>&lt;p&gt;netty-4.1.133-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;netty-4.1.133-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10795-1</guid>
    </item>
    <item>
      <title>RHSA-2026:53644 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.25 security pdate</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:53644</link>
      <description>&lt;p&gt;bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java bouncycastle: BC-JAVA: unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid bouncycastle: BC-JAVA: private key leakage via non-constant time comparisons picketlink-federation: auth bypass in Picketlink SAML unsolicited-response undertow-core: Undertow: Authentication Bypass via AJP ssl_cert/is_ssl Forgery jboss-marshalling-river: wildfly-clustering-infinispan-marshalling: Jboss Deserialization RCE via Unfiltered River Unmarshaller picketlink-federation: picketlink SAML 2.0 auth bypass via missing assertions openjdk-orb: unauthed class loading via IIOP in EAP undertow-core: OOM via missing limits in chunked trailer in EAP&amp;#39;s Undertow jboss-remoting: jboss-remoting: integer overflow in MessageReader leads to pre-authentication denial of service wildfly-iiop-openjdk: Missing authentication on EAP&amp;#39;s IIOP NameService leads to MITM or DoS undertow: undertow-websockets: Undertow: Pre-Auth DoS on websocket endpoint with @ServerEndpoint class with any @OnMessage method wildfly: wildfly-iiop: wildfly-jacorb: Wildfly: Pre-auth denial of service on the IIOP listener org.apache.artemis:artemis-server: org.apache.activemq:artemis-server: Apache Artemis, Apache ActiveMQ Artemis: Message injection and exfiltration du…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java bouncycastle: BC-JAVA: unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid bouncycastle: BC-JAVA: private key leakage via non-constant time comparisons picketlink-federation: auth bypass in Picketlink SAML unsolicited-response undertow-core: Undertow: Authentication Bypass via AJP ssl_cert/is_ssl Forgery jboss-marshalling-river: wildfly-clustering-infinispan-marshalling: Jboss Deserialization RCE via Unfiltered River Unmarshaller picketlink-federation: picketlink SAML 2.0 auth bypass via missing assertions openjdk-orb: unauthed class loading via IIOP in EAP undertow-core: OOM via missing limits in chunked trailer in EAP&amp;#39;s Undertow jboss-remoting: jboss-remoting: integer overflow in MessageReader leads to pre-authentication denial of service wildfly-iiop-openjdk: Missing authentication on EAP&amp;#39;s IIOP NameService leads to MITM or DoS undertow: undertow-websockets: Undertow: Pre-Auth DoS on websocket endpoint with @ServerEndpoint class with any @OnMessage method wildfly: wildfly-iiop: wildfly-jacorb: Wildfly: Pre-auth denial of service on the IIOP listener org.apache.artemis:artemis-server: org.apache.activemq:artemis-server: Apache Artemis, Apache ActiveMQ Artemis: Message injection and exfiltration du…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:53644</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-41417</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-41417</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: netty, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:Pro:22.04:LTS: netty, Ubuntu:Pro:24.04:LTS: netty, Ubuntu:25.10: netty, Ubuntu:Pro:26.04:LTS: netty&lt;/p&gt;
&lt;p&gt;Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: netty, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:Pro:22.04:LTS: netty, Ubuntu:Pro:24.04:LTS: netty, Ubuntu:25.10: netty, Ubuntu:Pro:26.04:LTS: netty&lt;/p&gt;
&lt;p&gt;Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-41417</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1372 — Netty: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1372</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Netty ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Netty ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1372</guid>
    </item>
  </channel>
</rss>
